CVE-2025-47729
LOW CISA KEVDescription
The TeleMessage archiving backend through 2025-05-05 holds cleartext copies of messages from TM SGNL (aka Archive Signal) app users, which is different functionality than described in the TeleMessage "End-to-End encryption from the mobile phone through to the corporate archive" documentation, as exploited in the wild in May 2025.
Is your site exposed to CVE-2025-47729?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild.
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| telemessage | text_message_archiver |
References
Other References
Frequently Asked Questions
What is CVE-2025-47729? +
How severe is CVE-2025-47729? +
What products are affected by CVE-2025-47729? +
How do I check if I'm vulnerable to CVE-2025-47729? +
Related Vulnerabilities
An insufficiently secured internal function allows session generation for arbitrary users. The decodeParam function checks the JWT but does not …
A remote code execution vulnerability exists in multiple Netcore and Netis routers models with firmware released prior to August 2014 …
Improper Validation of Integrity Check Value vulnerability in Sharp Display Solutions projectors allows a attacker may create and run unauthorized …
The "update" binary in the firmware of the affected product sends attempts to mount to a hard-coded, routable IP address, …
Longse model LBH30FE200W cameras, as well as products based on this device, provide an unrestricted access for an attacker located …
A static login vulnerability exists in the wctrls functionality of Wavlink AC3000 M33A8.V5030.210505. A specially crafted set of network packets …